Authorization Flaw in Pimcore Data Management Platform
CVE-2026-23494
What is CVE-2026-23494?
Pimcore, an Open Source Data & Experience Management Platform, has a significant vulnerability that allows authenticated users without the necessary permissions to access confidential API endpoints. Specifically, prior to versions 12.3.1 and 11.5.14, there was a failure in enforcing proper server-side authorization checks on the API endpoint for listing static routes. These static routes, which dictate custom URL patterns, can inadvertently expose sensitive configurations to unauthorized users. This issue has been addressed in the latest releases, emphasizing the importance of upgrading to ensure security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
pimcore >= 12.0.0-RC1, < 12.3.1 < 12.0.0-RC1, 12.3.1
pimcore < 11.5.14 < 11.5.14
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved